Duckcorp develops a narrowly focused product portfolio centered on the BIP application, which despite modest disclosure volume has attracted attention within its deployment context. The observed vulnerability surface reflects buffer-boundary issues that are characteristic of memory-handling in systems software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Duckcorp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0806MEDIUM Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of man | Jan 27, 2012 | 6.5 | 23 | NO | NO |
CVE-2010-3071MEDIUM bip before 0.8.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an empty USER command. | Oct 14, 2010 | 5.0 | 19 | NO | NO |
CVE-2011-5268MEDIUM connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of service (file descriptor consumption and crash) via multiple fa | Dec 24, 2013 | 4.3 | 17 | NO | NO |
CVE-2013-4550MEDIUM Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr before stderr has been closed, w | Dec 24, 2013 | 5.1 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Duckcorp.
Media articles that mention a CVE ID that affects a product developed by Duckcorp — matched by CVE ID, not by vendor name.